logo

SilkParasite APT Hits Central Asian Governments With 7 RATs

ID: accd65da-2a2b-5fe2-8259-b08c050a93f4

STIX ID: report--accd65da-2a2b-5fe2-8259-b08c050a93f4

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Do Son

...
...

Bitdefender Labs identified a China-nexus cyberespionage cluster dubbed SilkParasite that used seven RAT families to target government bodies across Central Asia (about 65 observed infections). Operators used spear-phishing with malicious Office documents, password-protected RAR lures, DLL sideloading with rotated signed hosts, and cloud-based C2 (Google Drive) to evade detection; researchers also observed artifacts consistent with AI-assisted development and found attribution signals pointing to a China-linked infrastructure and UTC+8 operator time zone.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.